GRC Engineer

Aegis AI

United States

On-site

USD 120,000 - 160,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

AegisAI is seeking a GRC Engineer to advance our security program. You will own SOC 2 end to end, maintain policy suite, and respond to security reviews that gate our biggest deals.

You'll work with the head of security, engineers, and the customers who ask the hard questions. What you build here becomes the reason deals close faster.

Qualifications

  • 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once.
  • you've answered enterprise security questionnaires and you write clearly enough that your answers close the thread.

Responsibilities

  • Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship.
  • Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track.
  • Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times.
  • Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them.
  • Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed.
  • Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast.
  • Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end.
  • Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can.
  • Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data.

Skills

GRC experience
SOC 2 Type II
Security questionnaires
Architecture diagrams
Python scripting
APIs
Privacy regimes knowledge

Tools

Automation scripts

Job description

Overview

We're a team of ex-Google engineers who built some of the largest defensive platforms on the planet — Safe Browsing and reCAPTCHA. Now, we're striking out on our own to tackle an even bigger challenge: stopping the new wave of adversarial AI attacks already hitting organizations today.

We're going after a $5B+ market, ripe for disruption. Traditional detection methods are too slow to keep up. Adversaries are using AI to craft customized, high-evasion attacks — and old-school rules-based systems don't stand a chance.

The Role

We're looking for a GRC Engineer to advance AegisAI's security program. We sell to security teams, which means our buyers grade us the way we grade our own vendors: audits, frameworks, questionnaires, policies, proof. Your job is to own that proof: keep it current, airtight, and fast to produce.

The title says engineer on purpose. We run compliance the way we run infrastructure: controls mapped once across frameworks, evidence collected automatically through APIs instead of screenshots, and an audit that falls out of how we operate every day rather than a yearly scramble. You'll own our SOC 2 end to end, keep our policies current as we scale, advance the business continuity and incident response muscle behind our customer commitments, and answer the security reviews that gate our biggest deals.

You'll work directly with the head of security, our engineers, and the customers who ask the hard questions. What you build here becomes the reason deals close faster.

What You'll Do

Own Compliance end to end: Keep the program audit-ready year round and run the auditor relationship.

Pave the road to what's next: Keep us ahead of what our customers ask for, so when the business needs its next certification or framework, we're already on track.

Run our risk management program: Maintain the risk register, keep treatments moving, and ensure we have an accurate picture of risk at all times.

Own the policy suite: Keep our policies, standards and procedures current as we grow, aligned with how we operate, and clear to the customers who read them.

Own BC/DR and incident response: Maintain and exercise our plans and playbooks, own the customer notification commitments behind them, and make sure everyone knows their part before it's needed.

Answer the questions that gate deals: Own customer security questionnaires and TPRM reviews end to end, grow the answer library so answers stay accurate and consistent, and keep turnaround fast.

Run vendor and subprocessor risk: Review the vendors we depend on, keep DPAs and the subprocessor list current, scale third-party risk management as our vendor footprint grows, and handle customer data requests end to end.

Map controls across frameworks: Maintain our control set against the industry frameworks we build on, audit against it, and make one piece of evidence count everywhere it can.

Expand evidence automation: Pull more proof straight from systems through APIs and scripts, so audits and questionnaires draw from live data.

Who You Are
  • 4+ years in GRC, security compliance or audit at a SaaS company, and you've run a SOC 2 Type II end to end at least once.

  • You've answered enterprise security questionnaires and you write clearly enough that your answers close the thread.

  • Technical enough to read an architecture diagram, question an engineer's answer, and tell the difference between a control that exists and one that's written down.

  • You script. Python or similar, comfortable with APIs, and allergic to collecting the same evidence twice.

  • Working knowledge of the major privacy regimes and what they mean for a data processor.

  • Organized, self-directed, and honest about what you don't know yet.

Bonus points:

  • You've implemented ISO 27001, or carried a company through certification.

  • Compliance automation platform experience, especially custom tests and the API side of one.

  • AI governance exposure: ISO 42001, NIST AI RMF, or building an AI policy from scratch.

  • You've built or tested BC/DR for a production SaaS.

  • Privacy certifications (CIPP or similar).

  • You've worked at a security vendor and know the standard your answers get held to.

Our Culture
  • Flat, flexible, and fast.

  • You'll own your decisions.

  • You'll have clear KPIs for success — but how you get there is up to you.

  • If you want compliance work that protects our customers and wins deals instead of filling binders, and want to work with a team that moves at the speed of the real world, join us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Aegis AI • United States

On-site
USD 120,000 - 190,000
GRC Manager
GRC Manager

OpenRouter, Inc • New York (NY)

On-site
USD 130,000 - 190,000
GRC Lead
GRC Lead

Hightouch • United States

Remote
USD 160,000 - 230,000
Equity compensation
GRC Manager
GRC Manager

OpenRouter, Inc • Northern (KY)

Hybrid
USD 120,000 - 180,000
GRC Lead
GRC Lead

Hightouch • San Francisco (CA)

On-site
USD 160,000 - 230,000
Security GRC Engineer
Security GRC Engineer

Cursor • Palo Alto (CA)

On-site
USD 180,000 - 240,000
GRC Engineer (Fully Remote)
GRC Engineer (Fully Remote)

Aegis AI • United States

Remote
USD 120,000 - 180,000
GRC and Security Compliance Lead
GRC and Security Compliance Lead

Openkrill • Northern (KY)

On-site
USD 120,000 - 190,000
Security Administrator
Security Administrator

Aegis AI Security • United States

On-site
USD 75,000 - 110,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • San Francisco (CA)

On-site
USD 140,000 - 200,000